Записи dotclear
32 опубликованных записей вендора dotclear.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-287 Improper Authentication1
- CWE-284 Improper Access Control1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
32 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2005-3957Эксплойта нет | Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.dotclear · dotclear | Критическая10,0 | — | 1,6 % | 1 дек. 2005 г. |
38Наблюдать | CVE-2008-3232Эксплойта нет | Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbdotclear · dotclear · CWE-94 | Критическая9,3 | — | 4,6 % | 18 июл. 2008 г. |
36Наблюдать | CVE-2016-7902Эксплойта нет | Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permidotclear · dotclear · CWE-434 | Высокая8,8 | — | 3,0 % | 4 янв. 2017 г. |
36Наблюдать | CVE-2015-8832Эксплойта нет | Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "dotclear · dotclear · CWE-284 | Высокая8,8 | — | 2,6 % | 9 февр. 2017 г. |
34Наблюдать | CVE-2023-53952Эксплойта нет | Dotclear 2.25.3 Authenticated Remote Code Execution via File Uploaddotclear · dotclear · CWE-434 | Высокая8,7 | — | 1,1 % | 19 дек. 2025 г. |
34Наблюдать | CVE-2024-58281Эксплойта нет | Dotclear 2.29 Remote Code Execution via Authenticated File Uploaddotclear · dotclear · CWE-434 | Высокая8,7 | — | 0,9 % | 10 дек. 2025 г. |
31Наблюдать | CVE-2011-5083Эксплойта нет | Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary coddotclear · dotclear · CWE-264 | Высокая7,5 | — | 3,3 % | 19 мар. 2012 г. |
31Наблюдать | CVE-2014-1613Эксплойта нет | Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-prdotclear · dotclear · CWE-94 | Высокая7,5 | — | 2,3 % | 16 мая 2014 г. |
30Наблюдать | CVE-2016-9268Эксплойта нет | Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows dotclear · dotclear · CWE-434 | Высокая7,2 | — | 5,0 % | 10 нояб. 2016 г. |
30Наблюдать | CVE-2005-3963Proof of concept | SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd dotclear · dotclear | Высокая7,5 | — | 1,4 % | 1 дек. 2005 г. |
27Наблюдать | CVE-2011-1584Эксплойта нет | The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, wdotclear · dotclear · CWE-264 | Средняя6,5 | — | 1,7 % | 8 июн. 2011 г. |
25Наблюдать | CVE-2015-8831Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scridotclear · dotclear · CWE-79 | Средняя6,1 | — | 2,1 % | 9 февр. 2017 г. |
24Наблюдать | CVE-2014-3781Эксплойта нет | The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via andotclear · dotclear · CWE-287 | Средняя5,8 | — | 2,2 % | 11 июн. 2014 г. |
24Наблюдать | CVE-2014-3783Эксплойта нет | SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pedotclear · dotclear · CWE-89 | Средняя6,0 | — | 1,7 % | 22 мая 2014 г. |
24Наблюдать | CVE-2016-6523Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary dotclear · dotclear · CWE-79 | Средняя6,1 | — | 1,3 % | 9 дек. 2016 г. |
24Наблюдать | CVE-2014-3782Эксплойта нет | Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow rdotclear · dotclear | Средняя6,0 | — | 1,2 % | 11 июн. 2014 г. |
24Наблюдать | CVE-2017-6446Эксплойта нет | XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.dotclear · dotclear · CWE-79 | Средняя6,1 | — | 0,7 % | 5 мар. 2017 г. |
24Наблюдать | CVE-2024-27626Эксплойта нет | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.dotclear · dotclear · CWE-79 | Средняя6,1 | — | 0,4 % | 20 мар. 2024 г. |
21Наблюдать | CVE-2006-2866Proof of concept | PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHPdotclear · dotclear | Средняя5,1 | — | 3,2 % | 6 июн. 2006 г. |
21Наблюдать | CVE-2006-3938Эксплойта нет | DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.phpdotclear · dotclear | Средняя5,0 | — | 2,3 % | 31 июл. 2006 г. |
21Наблюдать | CVE-2016-9891Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated usedotclear · dotclear · CWE-79 | Средняя5,4 | — | 1,0 % | 29 дек. 2016 г. |
21Наблюдать | CVE-2018-5689Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scridotclear · dotclear · CWE-79 | Средняя5,4 | — | 0,9 % | 14 янв. 2018 г. |
21Наблюдать | CVE-2018-5690Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scrdotclear · dotclear · CWE-79 | Средняя5,4 | — | 0,9 % | 14 янв. 2018 г. |
21Наблюдать | CVE-2018-16358Эксплойта нет | A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authedotclear · dotclear · CWE-79 | Средняя5,4 | — | 0,7 % | 2 сент. 2018 г. |
18Наблюдать | CVE-2012-1039Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML vdotclear · dotclear · CWE-79 | Средняя4,3 | — | 4,0 % | 19 мар. 2012 г. |
- CVE-2005-395740В плане
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %dotclear · dotclear1 дек. 2005 г.
- CVE-2008-323238Наблюдать
Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arb
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %dotclear · dotclear18 июл. 2008 г.
- CVE-2016-790236Наблюдать
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permi
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %dotclear · dotclear4 янв. 2017 г.
- CVE-2015-883236Наблюдать
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %dotclear · dotclear9 февр. 2017 г.
- CVE-2023-5395234Наблюдать
Dotclear 2.25.3 Authenticated Remote Code Execution via File Upload
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %dotclear · dotclear19 дек. 2025 г.
- CVE-2024-5828134Наблюдать
Dotclear 2.29 Remote Code Execution via Authenticated File Upload
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %dotclear · dotclear10 дек. 2025 г.
- CVE-2011-508331Наблюдать
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary cod
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %dotclear · dotclear19 мар. 2012 г.
- CVE-2014-161331Наблюдать
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-pr
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %dotclear · dotclear16 мая 2014 г.
- CVE-2016-926830Наблюдать
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows
ВысокаяCVSS 7,2Эксплойта нетEPSS 5 %dotclear · dotclear10 нояб. 2016 г.
- CVE-2005-396330Наблюдать
SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %dotclear · dotclear1 дек. 2005 г.
- CVE-2011-158427Наблюдать
The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, w
СредняяCVSS 6,5Эксплойта нетEPSS 2 %dotclear · dotclear8 июн. 2011 г.
- CVE-2015-883125Наблюдать
Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scri
СредняяCVSS 6,1Эксплойта нетEPSS 2 %dotclear · dotclear9 февр. 2017 г.
- CVE-2014-378124Наблюдать
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an
СредняяCVSS 5,8Эксплойта нетEPSS 2 %dotclear · dotclear11 июн. 2014 г.
- CVE-2014-378324Наблюдать
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pe
СредняяCVSS 6,0Эксплойта нетEPSS 2 %dotclear · dotclear22 мая 2014 г.
- CVE-2016-652324Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary
СредняяCVSS 6,1Эксплойта нетEPSS 1 %dotclear · dotclear9 дек. 2016 г.
- CVE-2014-378224Наблюдать
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow r
СредняяCVSS 6,0Эксплойта нетEPSS 1 %dotclear · dotclear11 июн. 2014 г.
- CVE-2017-644624Наблюдать
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %dotclear · dotclear5 мар. 2017 г.
- CVE-2024-2762624Наблюдать
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %dotclear · dotclear20 мар. 2024 г.
- CVE-2006-286621Наблюдать
PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP
СредняяCVSS 5,1Proof of conceptEPSS 3 %dotclear · dotclear6 июн. 2006 г.
- CVE-2006-393821Наблюдать
DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php
СредняяCVSS 5,0Эксплойта нетEPSS 2 %dotclear · dotclear31 июл. 2006 г.
- CVE-2016-989121Наблюдать
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated use
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dotclear · dotclear29 дек. 2016 г.
- CVE-2018-568921Наблюдать
Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scri
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dotclear · dotclear14 янв. 2018 г.
- CVE-2018-569021Наблюдать
Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scr
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dotclear · dotclear14 янв. 2018 г.
- CVE-2018-1635821Наблюдать
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authe
СредняяCVSS 5,4Эксплойта нетEPSS 1 %dotclear · dotclear2 сент. 2018 г.
- CVE-2012-103918Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML v
СредняяCVSS 4,3Proof of conceptEPSS 4 %dotclear · dotclear19 мар. 2012 г.